vendor:
Work The Flow File Upload
by:
Claudio Viviani, Roberto Soares Espreto
N/A
CVSS
N/A
Arbitrary File Upload
434
CWE
Product Name: Work The Flow File Upload
Affected Version From: 2.5.2002
Affected Version To: 2.5.2004
Patch Exists: YES
Related CWE: WPVDB 7883, EDB 36640
CPE: a:wordpress:work_the_flow_file_upload:2.5.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2015
WordPress Work The Flow Upload Vulnerability
This module exploits an arbitrary PHP code upload in the WordPress Work The Flow plugin, version 2.5.2. The vulnerability allows for arbitrary file upload and remote code execution.
Mitigation:
Update the plugin to the latest version